TLDRocket
18 September 2026
The day’s biggest throughline wasn’t just that AI agents can do work—it’s that they can do the wrong kind of work, at scale, and then force everyone else to scramble for proof they’re safe. A Hacktron team used Anthropic’s Claude to chain two vulnerabilities into access for multiple OpenAI employee ChatGPT accounts via OpenAI’s Discourse forum, then reported it and collected a $6,500 bug-bounty award. OpenAI says it has resolved the issues, but the incident lands a sharper point: fixes without rigorous vulnerability tracking don’t stay fixed in the messy reality of third-party software.
Read the full briefing →